Kubetier
  1. Create a pod with a gitRepo volume whose repository contains an ext:: command

  2. kubelet runs git clone as root, executing the injected command on the node

  3. Exfiltrate node credentials.

    This is T0 on control plane nodes

CVE-2024-10220↗CVE-2025-1767↗

Note:

The gitRepo driver is disabled by default in 1.33 and GA-locked off in 1.36, so the kubelet will not mount it.

The ext:: example shows the shape of the primitive, not a reproducible exploit: git has refused that transport by default since 2.12, independently of what CVE-2024-10220 turned on.

K8s docs ↗